Skip to content
Cyber Defense Technologies

Resources

Insights

Guidance on compliance, threats and security engineering from the people who do the work.

Insights

October 7, 2026 · 4 min read

Tabletop Exercises That Actually Prepare Your Team

An incident response plan that has never been practiced will fail in ways nobody expected. Tabletop exercises find those failures in a conference room instead of during a real attack. How to design, run and follow up on exercises that build real readiness.

Read more
Threat Intelligence

October 6, 2026 · 4 min read

Backups That Survive Ransomware

Ransomware operators know backups are the main reason victims refuse to pay, so they hunt for them first. How attackers target backups, what makes a backup resilient, and why a restore you have never tested is only a hope.

Read more
Insights

October 5, 2026 · 4 min read

Logging That Actually Helps an Investigation

When an incident happens, the first question is what the attacker did. The answer is only as good as the logs you kept. Which logs matter most, how long to keep them, what OMB M-21-31 requires of federal agencies, and how to make logs useful before you need them.

Read more
Threat Intelligence

October 4, 2026 · 4 min read

Prioritizing Vulnerabilities with KEV, EPSS and CVSS

Every scan produces more vulnerabilities than any team can fix at once. Severity scores alone point you at the wrong ones. How to combine CISA's Known Exploited Vulnerabilities catalog, the Exploit Prediction Scoring System and CVSS with your own context to fix what matters first.

Read more
Insights

October 3, 2026 · 4 min read

Zero Trust from Strategy to Practice

Zero trust has moved from buzzword to mandate. Federal agencies and the Department of War are working toward defined zero trust targets. What zero trust actually means, how the DoD pillars fit together, and where to start.

Read more
Insights

October 2, 2026 · 5 min read

Phishing-Resistant MFA: Why Some Second Factors Are Better Than Others

Multifactor authentication stops most password attacks, but attackers have learned to steal one-time codes and abuse push notifications. What makes MFA phishing-resistant, what federal policy requires, and how to roll it out without disrupting the mission.

Read more
Insights

October 1, 2026 · 5 min read

Cybersecurity Awareness Month: Four Habits That Still Stop Most Attacks

October is Cybersecurity Awareness Month. Most successful attacks still begin with a weak password, a missing patch or a convincing message. Four everyday habits, and how organizations can make them stick beyond October.

Read more
Compliance

September 22, 2026 · 5 min read

CMMC Explained: Levels, Assessments and Timelines for Defense Contractors

What the Cybersecurity Maturity Model Certification requires at each level, where the rollout stands after the Phase 2 suspension, and what defense contractors should be doing now.

Read more
Insights

September 15, 2026 · 4 min read

Drones as a Security Risk: What Facility Security Teams Should Know

Small unmanned aircraft are cheap, capable and widely available. How drones create physical and cyber risk for facilities and operations, what organizations can and cannot legally do about them, and how to start assessing exposure.

Read more

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.